KotoVPN

Glossary

DNS leak

When name lookups travel to your ISP’s resolver instead of through the tunnel, exposing every domain you visit.

Why it matters

A DNS leak defeats the point of the tunnel for observation purposes. Your ISP cannot read the encrypted traffic but can see the full list of sites you asked about, which is usually all an observer needs.

What most explanations leave out

Leaks are commonest on Windows, where the resolver may query several interfaces at once and use whichever answers first. A provider running its own resolvers on the same servers as the tunnel exit is the structural fix; a provider that hands you a third-party resolver has moved the problem rather than solved it.

Related terms

Kill switch

A control that blocks all internet traffic if the VPN tunnel drops, rather than letting it fall back to your normal connection.

IPv6 leak

When a tunnel carries only IPv4 while your connection also has IPv6, so IPv6-capable sites see your real address.

WebRTC leak

When a browser exposes your local or real address through the peer-connection API, independently of the VPN tunnel.

Referenced from

Terms are defined here because they appear in our scoring rubric or in provider reviews, not to fill a glossary.